l3montree-dev / l3montree-dev/devguard

Display of Dependency Proxy Data in the overview Tab

Open
#2,858 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

component/devguard-api component/devguard-web feature-request
Dominant language
Go
Stars
161
Forks
43
Avg merge
1d 8h
Merged PRs (30d)
37

Description

Since more Data is always great (especially when structured), a Dependency Proxy Data display could be a nice addition to the Group or Repo.

It could be good to see:

  • How many package Downloads has been blocked and why:
    • Malicious Dependency
    • Dependency version to young
  • How many dependencies are checked in total (and how many downloads are blocked (percentage) - nice for general data collection and security report generation)?
  • General dependency inventory listing for the whole company (like an organization-wide SBOM) - as a basis for a general dependency audit with a security team or as a basis for GS++ DEV.4.2.

What do you think @timbastin & @seb-kw ?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Dependency Proxy data sources and the Group or Repo overview tab entry point. Clarify which blocked-download metrics, dependency totals, and inventory or SBOM scope are required before implementation. Done means the agreed Dependency Proxy data is displayed with verifiable counts and security-report inventory coverage.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
backend, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.